Privacy Policy GDPR Compliant
Citeable ("we", "us", "our") is a Shopify application that helps merchants understand and improve their AI search visibility. This Privacy Policy explains what information we collect when you install and use Citeable, how we use it, and how you can control it.
1. What Data We Collect
- Store domain — your Shopify store's
.myshopify.comdomain, used to identify your account and associate scans. - Order referrer URLs — the HTTP referrer header from incoming orders, used to detect whether orders were referred by AI channels (ChatGPT, Perplexity, Gemini, etc.).
- Product catalog data — product titles, descriptions, meta descriptions, and image alt text from your Shopify catalog, fetched via the Shopify Admin API for AI readiness scoring and optimization suggestions.
- GEO audit scores — computed AI visibility scores and audit results for your store, stored to power the history and trend features.
- Settings — optional store display name, contact email, and report preferences you provide in the Settings page.
- OAuth session tokens — Shopify access tokens required by Shopify's authentication system, stored securely in our database.
We do not collect, store, or process any customer personally identifiable information (PII), including customer names, email addresses, payment information, physical addresses, or any other personal data belonging to your customers.
2. How We Use Your Data
- AI Visibility Scoring (GEO Score) — product and store data is analyzed to produce a score reflecting how well your store is optimized for AI search engines. Scoring runs on our servers and results are stored for trend tracking.
- Revenue Attribution — order referrer URLs are checked against known AI channel domains to attribute revenue to AI traffic sources (ChatGPT, Perplexity, Gemini, Copilot, Claude).
- Optimization Suggestions — product descriptions, meta descriptions, and image alt text are processed by an AI language model (Groq / Llama) to generate improvement suggestions. This processing is performed on-demand when you request it.
- Weekly Reports — if enabled, your GEO score and attribution summary are sent to the email address you provide in Settings.
- Competitor Analysis — competitor domains you enter are externally audited (we fetch their robots.txt, schema markup, and llms.txt) to produce a comparison. No data from competitor sites is stored beyond the computed scores.
3. Data Sharing and Third Parties
- Groq (AI processing) — product content is sent to Groq's API (using Llama 3.1) for generating optimization suggestions. Data is processed per Groq's privacy policy and is not used for training.
- Shopify — we access your store via Shopify's Admin API using scopes you authorize. We do not share your data with Shopify beyond what is required by Shopify's platform agreements.
- We do not sell, rent, or share your store data with any other third parties, advertisers, or data brokers.
4. Data Retention
- All store data — including GEO scores, attributed orders, competitor records, product scores, and sessions — is permanently deleted within 48 hours of app uninstall.
- Weekly report emails are not retained; they are delivered and immediately discarded.
- You may request deletion of your data at any time by emailing us at support@dazzletech.co.
5. GDPR Compliance
If you are based in the European Economic Area (EEA) or your customers are EEA residents, the following applies:
- Legal basis for processing — we process your store data under the legitimate interests of providing the Citeable service you have contracted for (GDPR Article 6(1)(b) and 6(1)(f)).
- No customer PII stored — because we do not store any customer personal data, no data subject access requests apply to end customers through Citeable.
- Merchant rights — as a merchant, you have the right to access, correct, or delete your store's data. Email support@dazzletech.co to exercise these rights.
- Data transfers — our servers are located in the European Union / United States. Data transferred to Groq for AI processing is subject to Groq's standard contractual clauses.
- GDPR Webhook compliance — Citeable responds to all three mandatory Shopify GDPR webhooks:
customers/data_request,customers/redact, andshop/redact. Because no customer PII is stored, data request and redaction webhooks are acknowledged with an empty dataset response.
6. Security
Shopify access tokens are stored in an encrypted SQLite database. All data is transmitted over HTTPS. We follow Shopify's security best practices for embedded apps. We do not log or store raw order payloads beyond the referrer URL and revenue amount.
7. Children's Privacy
Citeable is a business tool intended for adult merchants. We do not knowingly collect data from individuals under 16.
8. Changes to This Policy
We may update this Privacy Policy as the app evolves. Material changes will be communicated via in-app notification or email to the address registered in your Settings. Continued use after notice constitutes acceptance.
Dazzletech · Citeable
Email: support@dazzletech.co
Response time: within 24 business hours